Comment 15 for bug 1980018

Revision history for this message
Steve Langasek (vorlon) wrote : Re: [Bug 1980018] Re: Cryptsetup-initramfs cant deal with tpm2-device option

On Thu, Sep 08, 2022 at 04:54:33PM -0000, W McElderry wrote:
> @vorlon

> Thanks for the comment. I'm interested in TPMs and have been for a
> while, so I'd love to hear more about the vulnerabilities you mention.
> Can you recommend somewhere to get more info?

I don't know of anything specifically published about this. But the root
issue is that if you load an initramfs, the initramfs is not measured, so
can be modified to steal control of the encrypted disk.